Skip to main content

The Coldcard Hack Just Hit $116 Million. A Fourth Wave Is Still Draining

Importance Critical

The Coldcard hardware wallet hack has grown to $116 million (potentially more) across four separate waves, and Coinkite says the last three days have been among the hardest in the company’s history.

Four Waves in Four Days

What started as an estimated $30 million theft has more than tripled in less than a week. Bitcoin.com News first reported the exploit as it emerged, with the figure climbing with each new wave of transactions attackers have pulled from Coldcard-generated wallets: from an initial burst that moved $30 million in the opening ten minutes, to roughly $75 million after a second wave, to nearly $89 million as the theft spread to 4,500 addresses. The figure now stands at approximately $116 million across 1,816 BTC pulled from more than 5,200 individual addresses. Galaxy Research, which has tracked the exploit in real time, confirmed a fourth wave on August 3 that alone moved roughly 449 BTC after corrections to earlier figures.

Alex Thorn, head of Galaxy Research, described the latest activity as a probable “fourth organized wave” of thefts, pointing to a sweep rate of 13.8 transfers per block against a pre-incident control window of just 0.3 transfers per block, or roughly 45 times normal baseline activity. Thorn’s analysis suggests the pattern points to multiple groups racing in parallel across the vulnerable key space rather than a single attacker methodically expanding their operation, implying the theft could continue in bursts as different actors independently discover which addresses remain exposed.

Why the Random Number Flaw Matters

The root cause traces back to a 2021 firmware update to certain Coldcard devices that switched the wallet’s seed-generation process from a strong hardware-based randomness source to a software pattern that turned out to be predictable. Any wallet seed created on the affected firmware could, in theory, be guessed rather than brute-forced. During the early scramble, ZachXBT declined to help trace the stolen funds, leaving victims and independent researchers racing against attackers who already understood which addresses were vulnerable. Attackers targeted the biggest balances within minutes, pulling hundreds of bitcoin from single-signature wallets within 25 minutes before most holders had any indication their funds were at risk. All compromised addresses trace back to wallet seeds generated after the flawed firmware shipped in March 2021, meaning the exposure window has existed for more than five years.

Coinkite’s Response and What Comes Next

Coinkite, the Canadian manufacturer behind Coldcard, acknowledged the scale of the damage directly. In a statement, the company said “the last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” and strongly advised anyone who generated a wallet seed on a Coldcard device to move their funds to a new, safely generated wallet as soon as possible. Victims still working through the process have a narrow window to attempt Replace-By-Fee transactions on unconfirmed transfers, though that option only helps if an attacker’s sweep has not already confirmed onchain. Industry personnel like Anthony Pompliano have pushed back on the narrative that the hack was on bitcoin itself, arguing that the flaw sat squarely in Coldcard’s firmware rather than the BTC protocol.

Source: https://news.bitcoin.com/security/coldcard-hack-116-million-fourth-wave/